Now Building
Enterprise Homelab Progress
Last updated: August 26, 2026
Current Focus
Homelab workloads continue migrating into role-specific network segments. Security, analysis, development, lab, and identity systems were remapped and validated after infrastructure changes. Internal name resolution was updated, a hardened firewall policy was implemented, and Elastic storage capacity was expanded. Remaining work includes finishing Elastic storage configuration, broadening agent coverage, and validating detections.
Timeline
- 2026-08-26DCP-005 — segmented workload migration, DNS updates, firewall hardening, Elastic storage expansion
- 2026-08-09DCP-005 — HTB analysis VMs, storage expansion, VLAN segmentation started
- 2026-08-06DCP-005 — observability hardening, threat intel, partial snapshots
- 2026-08-03DCP-005 in progress — ELK/Fleet telemetry, lab & analysis workloads, AD OU model
- 2026-08-03DCP-004 completed — golden templates including REMnux
- 2026-07-29DCP-004 — Windows and Linux golden templates converted
- 2026-07-27DCP-003 — AD, DNS, DHCP, WireGuard, management networking
- 2026-07-20DCP-002 — OPNsense, WiFi bridge, Proxmox networking
- 2026-07-19DCP-001 completed — Proxmox foundation
- TBDDCP-006 — Detection engineering loop
Progress Indicators
- WiFi BridgeComplete
- OPNsenseComplete
- Internal NetworkingComplete
- Network SegmentationIn Progress
- Infrastructure FoundationComplete
- Active DirectoryComplete
- DNSComplete
- DHCPComplete
- WireGuard VPNComplete
- Golden TemplatesComplete
- Elastic / MonitoringIn Progress
- Analysis WorkloadsIn Progress
Completed Milestones
Proxmox Foundation
Installed and hardened Proxmox VE, created backup administrator accounts, disabled root GUI login, and established enterprise VM pools.
Networking & Edge Foundation
Built the WiFi edge bridge, installed OPNsense, configured Proxmox bridges, uploaded ISOs, and created the Domain Controller VM shell.
Identity & Remote Access Baseline
Deployed Active Directory, DNS, and DHCP on Windows Server 2025; completed OPNsense routing and WireGuard VPN; improved Proxmox management networking.
Golden Templates / Telemetry Prep
Built reusable Windows and Linux golden images, including REMnux template infrastructure, for consistent lab deployments.
Upcoming Milestones
Telemetry Platform
Operate and harden Elastic Stack and Fleet, migrate workloads into role-specific segments, expand analysis capacity, and prepare detection validation. Status: In Progress (~80%).
Detection Engineering Loop
Validate first detections end-to-end against lab telemetry.
Infrastructure Inventory
Edge Bridge
ActiveWiFi-to-Ethernet edge bridge
Upstream connectivity path for the Proxmox host and lab edge.
Lab Firewall
OperationalFirewall, router, and VPN gateway
Edge security boundary with hardened policy and verified remote access.
Domain Controller
OperationalActive Directory, DNS, and DHCP
Identity plane with organizational-unit foundations and updated name resolution.
Golden Templates
CompleteStandardized lab OS images
Windows, Ubuntu, Kali, and REMnux templates migrated to expanded storage.
Security Monitoring
In ProgressElastic Stack and Fleet
Hardened internal platform with expanded storage capacity and validated web access after network changes.
Lab & Analysis Workloads
DeployedEndpoint, offensive, and malware-analysis systems
Windows lab endpoint, Kali lab guest, REMnux, and dedicated HTB/DFIR analysis guests online in segmented networks.
Development Automation
DeployedAI-assisted development host
Development VM online on the development segment.
Architecture Overview
Live architecture: Internet to home router to WiFi edge bridge into Proxmox. The lab firewall provides routing, hardened policy, and VPN remote access. Active Directory supplies identity, DNS, and DHCP. Golden templates accelerate guest builds. An internal Elastic Stack with Fleet collects endpoint telemetry, with threat-intelligence enrichment and expanded storage capacity. Workloads are migrating into role-specific network segments for identity, security, analysis, development, and lab use. Detection validation remains open.
Roadmap
Foundation
complete100%
- Proxmox VE hardened and managed on the lab network
- Enterprise VM pools and ISO library
- Golden OS templates complete
Infrastructure
in progress78%
- Domain Controller operational
- Lab, analysis, development, and security workloads deployed
- Backup job cadence (remaining)
Networking
in progress85%
- OPNsense edge firewall and routing
- Internal lab network
- WireGuard remote access
- Role-specific segmentation advanced (validation remaining)
Security
in progress75%
- Active Directory domain and OU foundations
- DNS and DHCP on the domain controller
- Hardened firewall policy implemented
- GPO baselines and AD CS (remaining)
Monitoring
in progress80%
- Elastic Stack online for internal monitoring
- Observability and Security validated for a Windows lab endpoint
- Threat-intelligence feed and auditing enabled
- Expanded Elastic storage capacity (configuration remaining)
- Expanded agent coverage (remaining)
Detection Engineering
planned5%
- Detection-as-code workflow
- Validation against live Sysmon telemetry
Threat Hunting
planned0%
- Hunt hypotheses and case studies
Automation
planned20%
- Status sync automation
- Golden-image maintainability patterns
- AI development host online
Portfolio
in progress58%
- Lab Progress sync
- Public infrastructure narrative
- Progress writeups
Recent Changes
Migrated security, analysis, development, lab, and identity workloads into role-specific network segments; updated internal name resolution including reverse zones; implemented a hardened firewall policy; expanded Elastic storage capacity; and validated service availability after the changes.
Added dedicated Windows and Linux analysis environments for authorized lab work, installed additional virtualization storage and migrated golden templates, and began network segmentation.
Hardened the Elastic monitoring platform, added threat-intelligence enrichment, validated endpoint observability after time-sync remediation, and captured known-good snapshots for critical monitoring and edge systems.
Advanced Active Directory organizational foundations, deployed Windows and Kali lab endpoints, stood up REMnux analysis capacity, and brought an internal Elastic Stack online with Fleet-based Sysmon telemetry from a domain-joined workstation.
Recently Completed
- Migrated applicable workloads into role-specific network segments
- Updated internal DNS and reverse lookup coverage for segmented networks
- Implemented hardened firewall policy and expanded remote-access reachability
- Expanded Elastic storage capacity
- Validated service availability after infrastructure changes
- Expanded Windows and Linux analysis capacity for lab and DFIR practice
- Installed additional virtualization storage and migrated golden templates
- Hardened Elastic monitoring accounts, keys, and break-glass practices
- Enabled Elasticsearch auditing and system-log data views
- Added AlienVault OTX threat-intelligence feed
- Validated Windows lab endpoint visibility in Observability and Security
- Established Active Directory organizational-unit foundations
Evidence & Diagrams
Screenshots
Architecture Diagram
Build Narrative
Enterprise Homelab Progress
The ElliottSecurity Enterprise Homelab runs on Proxmox VE with an OPNsense edge firewall, identity services, reusable golden images, and an internal Elastic Stack. DCP-005 is in progress: segmented networking advanced on 2026-08-26 with migrated workloads, updated name resolution, firewall hardening, and expanded Elastic capacity. Detection validation and broader telemetry coverage remain open.
Current Focus
Homelab workloads continue migrating into role-specific network segments. Security, analysis, development, lab, and identity systems were remapped and validated after infrastructure changes. Internal name resolution was updated, a hardened firewall policy was implemented, and Elastic storage capacity was expanded. Remaining work includes finishing Elastic storage configuration, broadening agent coverage, and validating detections.
Progress Indicators
- WiFi Bridge — complete
- OPNsense — complete
- Internal Networking — complete
- Network Segmentation — in progress
- Infrastructure Foundation — complete
- Active Directory — complete
- DNS — complete
- DHCP — complete
- WireGuard VPN — complete
- Golden Templates — complete
- Elastic / Monitoring — in progress
- Analysis Workloads — in progress
Timeline
- 2026-08-26 — DCP-005 — segmented workload migration, DNS updates, firewall hardening, Elastic storage expansion
- 2026-08-09 — DCP-005 — HTB analysis VMs, storage expansion, VLAN segmentation started
- 2026-08-06 — DCP-005 — observability hardening, threat intel, partial snapshots
- 2026-08-03 — DCP-005 in progress — ELK/Fleet telemetry, lab & analysis workloads, AD OU model
- 2026-08-03 — DCP-004 completed — golden templates including REMnux
- 2026-07-29 — DCP-004 — Windows and Linux golden templates converted
- 2026-07-27 — DCP-003 — AD, DNS, DHCP, WireGuard, management networking
- 2026-07-20 — DCP-002 — OPNsense, WiFi bridge, Proxmox networking
- 2026-07-19 — DCP-001 completed — Proxmox foundation
- TBD — DCP-006 — Detection engineering loop
Completed Milestones
- DCP-001 — Proxmox Foundation (2026-07-19): Installed and hardened Proxmox VE, created backup administrator accounts, disabled root GUI login, and established enterprise VM pools.
- DCP-002 — Networking & Edge Foundation (2026-07-20): Built the WiFi edge bridge, installed OPNsense, configured Proxmox bridges, uploaded ISOs, and created the Domain Controller VM shell.
- DCP-003 — Identity & Remote Access Baseline (2026-07-27): Deployed Active Directory, DNS, and DHCP on Windows Server 2025; completed OPNsense routing and WireGuard VPN; improved Proxmox management networking.
- DCP-004 — Golden Templates / Telemetry Prep (2026-08-03): Built reusable Windows and Linux golden images, including REMnux template infrastructure, for consistent lab deployments.
Upcoming Milestones
- DCP-005 — Telemetry Platform: Operate and harden Elastic Stack and Fleet, migrate workloads into role-specific segments, expand analysis capacity, and prepare detection validation. Status: In Progress (~80%).
- DCP-006 — Detection Engineering Loop: Validate first detections end-to-end against lab telemetry.
Infrastructure Inventory
- Edge Bridge (Active): Upstream connectivity path for the Proxmox host and lab edge.
- Lab Firewall (Operational): Edge security boundary with hardened policy and verified remote access.
- Domain Controller (Operational): Identity plane with organizational-unit foundations and updated name resolution.
- Golden Templates (Complete): Windows, Ubuntu, Kali, and REMnux templates migrated to expanded storage.
- Security Monitoring (In Progress): Hardened internal platform with expanded storage capacity and validated web access after network changes.
- Lab & Analysis Workloads (Deployed): Windows lab endpoint, Kali lab guest, REMnux, and dedicated HTB/DFIR analysis guests online in segmented networks.
- Development Automation (Deployed): Development VM online on the development segment.
Architecture Overview
Live architecture: Internet to home router to WiFi edge bridge into Proxmox. The lab firewall provides routing, hardened policy, and VPN remote access. Active Directory supplies identity, DNS, and DHCP. Golden templates accelerate guest builds. An internal Elastic Stack with Fleet collects endpoint telemetry, with threat-intelligence enrichment and expanded storage capacity. Workloads are migrating into role-specific network segments for identity, security, analysis, development, and lab use. Detection validation remains open.
Roadmap
Foundation
-
Status: complete
-
Progress: 100%
- Proxmox VE hardened and managed on the lab network
- Enterprise VM pools and ISO library
- Golden OS templates complete
Infrastructure
-
Status: in-progress
-
Progress: 78%
- Domain Controller operational
- Lab, analysis, development, and security workloads deployed
- Backup job cadence (remaining)
Networking
-
Status: in-progress
-
Progress: 85%
- OPNsense edge firewall and routing
- Internal lab network
- WireGuard remote access
- Role-specific segmentation advanced (validation remaining)
Security
-
Status: in-progress
-
Progress: 75%
- Active Directory domain and OU foundations
- DNS and DHCP on the domain controller
- Hardened firewall policy implemented
- GPO baselines and AD CS (remaining)
Monitoring
-
Status: in-progress
-
Progress: 80%
- Elastic Stack online for internal monitoring
- Observability and Security validated for a Windows lab endpoint
- Threat-intelligence feed and auditing enabled
- Expanded Elastic storage capacity (configuration remaining)
- Expanded agent coverage (remaining)
Detection Engineering
-
Status: planned
-
Progress: 5%
- Detection-as-code workflow
- Validation against live Sysmon telemetry
Threat Hunting
-
Status: planned
-
Progress: 0%
- Hunt hypotheses and case studies
Automation
-
Status: planned
-
Progress: 20%
- Status sync automation
- Golden-image maintainability patterns
- AI development host online
Portfolio
-
Status: in-progress
-
Progress: 58%
- Lab Progress sync
- Public infrastructure narrative
- Progress writeups
Recent Changes
- 2026-08-26 — DCP-005 — Segmented workload migration and reliability: Migrated security, analysis, development, lab, and identity workloads into role-specific network segments; updated internal name resolution including reverse zones; implemented a hardened firewall policy; expanded Elastic storage capacity; and validated service availability after the changes.
- 2026-08-09 — DCP-005 — Analysis expansion and segmentation: Added dedicated Windows and Linux analysis environments for authorized lab work, installed additional virtualization storage and migrated golden templates, and began network segmentation.
- 2026-08-06 — DCP-005 — Observability hardening and reliability: Hardened the Elastic monitoring platform, added threat-intelligence enrichment, validated endpoint observability after time-sync remediation, and captured known-good snapshots for critical monitoring and edge systems.
- 2026-08-03 — DCP-005 — Telemetry platform and lab workloads: Advanced Active Directory organizational foundations, deployed Windows and Kali lab endpoints, stood up REMnux analysis capacity, and brought an internal Elastic Stack online with Fleet-based Sysmon telemetry from a domain-joined workstation.
Recently Completed
- Migrated applicable workloads into role-specific network segments
- Updated internal DNS and reverse lookup coverage for segmented networks
- Implemented hardened firewall policy and expanded remote-access reachability
- Expanded Elastic storage capacity
- Validated service availability after infrastructure changes
- Expanded Windows and Linux analysis capacity for lab and DFIR practice
- Installed additional virtualization storage and migrated golden templates
- Hardened Elastic monitoring accounts, keys, and break-glass practices
- Enabled Elasticsearch auditing and system-log data views
- Added AlienVault OTX threat-intelligence feed
- Validated Windows lab endpoint visibility in Observability and Security
- Established Active Directory organizational-unit foundations
Screenshots Placeholder
Screenshots pending for Elastic Fleet status and AD OU evidence (redacted).
Architecture Diagram Placeholder
Architecture diagram placeholder — high-level Mermaid overview below; static export assets TBD.
Mermaid Diagram Placeholder
flowchart TB
Internet((Internet)) --> HomeRouter[Home Router]
HomeRouter --> EDGE["Edge Bridge"]
EDGE --> PX["Proxmox Host"]
Remote["Remote clients"] -->|VPN| FW
PX --> FW["Lab Firewall / Router / VPN"]
FW --> EDGE
PX --> ID["Identity · DNS · DHCP"]
PX --> MON["Elastic Stack / Fleet"]
PX --> LAB["Lab & Analysis Workloads"]
PX --> DEV["Development / Automation"]
LAB -->|"Endpoint telemetry"| MON